Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-29622

Опубликовано: 16 мая 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. Strapi does not consider this to be a valid vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:formidable_project:formidable:3.1.4:*:*:*:*:node.js:*:*

EPSS

Процентиль: 96%
0.24201
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. Strapi does not consider this to be a valid vulnerability.

CVSS3: 9.8
debian
больше 3 лет назад

An arbitrary file upload vulnerability in formidable v3.1.4 allows att ...

CVSS3: 9.8
github
больше 3 лет назад

Formidable arbitrary file upload

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость библиотеки Formidable, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.24201
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434